Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
77 results
WebSecProbe preview

WebSecProbe

GitHubspyboy-productions/websecprobe

Security testing tool for analyzing HTTP 403 responses and identifying access control misconfigurations in web applications.

misconfigurationpenetration-testingvulnerability-scanners+2
188
9 months ago
CVE-2018-16763 preview

CVE-2018-16763

GitHubsome-1hing/cve-2018-16763

Python tool for analyzing CVE-2018-16763 in FUEL CMS with cleaner response parsing and interactive vulnerability checking.

code-analysisexploitationpenetration-testing+3
4 months ago
CVE-2025-0108-Authentication-Bypass-checker preview

CVE-2025-0108-Authentication-Bypass-checker

GitHubbarcrange/cve-2025-0108-authentication-bypass-checker

Python script that tests PAN-OS devices for CVE-2025-0108 authentication bypass by sending crafted HTTP requests and analyzing responses.

authenticationexploitationpenetration-testing+3
1 year ago
dalfox preview

dalfox

GitHubhahwul/dalfox

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

devsecopsdynamic-code-analysispenetration-testing+5
5.3k1 day ago
TInjA preview

TInjA

GitHubhackmanit/tinja

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

dynamic-code-analysisfuzzingpenetration-testing+3
4305 months ago
grafanaExp preview

grafanaExp

GitHuba-d-team/grafanaexp

A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt…

encryption-decryption-toolsexploitationinformation-gathering+3
26911 months ago
pax preview

pax

GitHubliamg/pax

:skull: :unlock: CLI tool for PKCS7 padding oracle attacks

cryptographyexploitationpenetration-testing+1
1455 years ago
dp_cryptomg preview

dp_cryptomg

GitHubblacklanternsecurity/dp_cryptomg

Another tool for exploiting CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX dialog handler.

cryptographyexploitationpenetration-testing+3
611 month ago
CVE-2022-22947 preview

CVE-2022-22947

GitHubsijido/cve-2022-22947

Python-based memory shell injection tool for CVE-2022-22947, supporting Spring, Netty, and Godzilla memory shells with simple CLI usage.

exploitationmemory-forensicsvulnerability-analysis+1
94 years ago
CVE_2023_44487-Rapid_Reset preview

CVE_2023_44487-Rapid_Reset

GitHubmadhusudhan-in/cve_2023_44487-rapid_reset

A comprehensive Python testing tool for CVE-2023-44487, the HTTP/2 Rapid Reset vulnerability. This enhanced version provides granular control over…

exploitationnetwork-securitypenetration-testing+3
12 months ago
Fortinet-CVE-2022-40684 preview

Fortinet-CVE-2022-40684

GitHubjsongmax/fortinet-cve-2022-40684

Go-based exploit tool for CVE-2022-40684 (Fortinet authentication bypass). Automates SSH key injection for authorized penetration testing and…

exploitationnetwork-securitypenetration-testing+3
23 years ago
CVE-2024-38063-Exploit-Refactoring preview

CVE-2024-38063-Exploit-Refactoring

GitHubarrhenius975/cve-2024-38063-exploit-refactoring

Python-based exploit for CVE-2024-38063 targeting Windows IPv6 vulnerability. Automates network interface detection, packet crafting, and…

exploitationnetwork-securitypayload-generation+3
7 months ago
Tenda-F3-V4 preview

Tenda-F3-V4

GitHub4d000/tenda-f3-v4

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

embedded-systems-securityexploitationfirmware-analysis+4
31 year ago
wafw00f preview

wafw00f

GitHubenablesecurity/wafw00f

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

crawlerdynamic-code-analysisinformation-gathering+6
6.6k5 months ago
SSTImap preview

SSTImap

GitHubvladko312/sstimap

Automatic SSTI detection tool with interactive interface

code-analysiscommand-and-controldynamic-code-analysis+6
1.7k1 month ago
MITMer preview

MITMer

GitHubhusam212/mitmer

Automated man-in-the-middle attack tool.

dns-analysisnetwork-securitypacket-sniffing-analysis+5
5312 years ago
watchTowr-vs-Citrix-Netscaler-CVE-2026-88772 preview

watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

GitHubwatchtowrlabs/watchtowr-vs-citrix-netscaler-cve-2026-88772

Detection artifact generator for Citrix NetScaler CVE-2026-88772 that builds a DTLS pre-auth buffer overflow payload to verify remote code execution.

exploitationnetwork-securitypenetration-testing+3
711 days ago
CVE-2024-47176 preview

CVE-2024-47176

GitHubaytackalinci/cve-2024-47176

Vulnerability Scanner for CUPS: CVE-2024-47176

exploitationnetwork-securitypenetration-testing+3
28 months ago
Previous12345Next